Executive Summary
A multi-purpose specialty chemical plant had accumulated a set of HAZOP recommendations calling for instrumented safeguards across several process campaigns, without a consistent methodology for determining how reliable each safeguard actually needed to be. Safeguard specification had, in practice, been decided informally on a case-by-case basis by whichever engineer reviewed the relevant HAZOP action, resulting in inconsistent rigor across functionally similar scenarios. This representative example illustrates a combined LOPA and SIL program bringing consistent, quantified rigor to safeguard specification across a multi-product facility's accumulated HAZOP findings.
Facility Background
The facility operated as a multi-purpose plant running several distinct chemistries across shared reactor and utility infrastructure, with a HAZOP program that had, over successive campaigns, generated a backlog of recommendations for additional instrumented protection against various high-severity deviations. Because these recommendations arose from different HAZOP sessions conducted over time, often with different facilitators and without a shared quantitative basis, the resulting safeguard specifications varied in rigor — some scenarios received elaborate instrumented protection while comparably severe scenarios elsewhere in the facility received only a basic alarm, without a documented risk-based justification for the difference.
Hazard Profile
- —High-severity HAZOP-flagged deviations spanning multiple distinct process chemistries sharing common reactor infrastructure
- —Inconsistent safeguard rigor across functionally similar scenarios, reflecting the absence of a shared quantitative risk basis
- —Shared utility and instrumentation infrastructure across campaigns, raising common cause failure considerations between safeguards nominally protecting different processes
- —Backlog of unresolved HAZOP recommendations lacking a prioritisation basis for which warranted the most urgent safeguard investment
Study Methodology
- 1.Consolidation of high-severity HAZOP recommendations across all prior campaign studies into a single scenario set for LOPA treatment
- 2.LOPA workshops conducted scenario-by-scenario, assigning initiating event frequencies and identifying genuinely independent protection layers for each
- 3.Target SIL determination for scenarios where existing and credited protection layers left a documented risk reduction gap
- 4.SIL verification for the resulting safety instrumented functions, covering architecture, failure rate data, and proof test interval requirements per IEC 61511
- 5.Common cause failure review across safety instrumented functions sharing utility or instrumentation infrastructure between different process campaigns
- 6.Consolidated Safety Requirements Specification issued covering all 11 resulting safety instrumented functions with a consistent documented basis
Key Findings
- —LOPA quantification revealed that several previously informally specified safeguards were, in fact, appropriately rated, while others were under-specified relative to their actual required risk reduction
- —Two scenarios initially treated as comparable in severity were found to require different target SILs once initiating event frequency and existing protection layer credit were properly quantified
- —Common cause failure analysis identified a shared logic solver serving safety instrumented functions across two different process campaigns, a dependency not previously documented or assessed
- —The consolidated scenario review surfaced one HAZOP recommendation that had never been formally closed, effectively leaving a required safeguard unimplemented
Risk Reduction Measures
- —Eleven safety instrumented functions established with LOPA-derived target SILs and verified architecture, replacing the prior ad-hoc, campaign-by-campaign specification approach
- —Proof test intervals defined consistently across all eleven SIFs based on their verified PFDavg requirements, rather than varying by whichever engineer had originally specified each safeguard
- —The shared logic solver dependency addressed through revised common cause failure treatment in the SIL verification calculations for the affected functions
- —The previously unclosed HAZOP recommendation implemented as part of the consolidated program, closing a longstanding gap
Lessons Learned
Safeguard specification consistency requires a shared quantitative method, not just shared engineering judgment.
Individually competent engineers, each reviewing HAZOP recommendations in isolation over time, still produced inconsistent safeguard rigor — the fix was a shared LOPA-based quantitative method applied consistently across the accumulated recommendation backlog, not simply better individual judgment.
A backlog of HAZOP recommendations is itself a risk management gap worth addressing directly.
Recommendations generated across multiple campaigns without a consolidation exercise can silently leave inconsistent or even unimplemented safeguards in place; treating the backlog as a program-level LOPA exercise, not a queue of independent minor tasks, surfaced gaps individual review would likely have missed.
Shared infrastructure across a multi-product facility can undermine SIF independence in ways not obvious campaign-by-campaign.
The shared logic solver dependency was only visible once safety instrumented functions from different campaigns were reviewed together under a single common cause failure analysis, rather than being assessed independently as part of each campaign's separate safeguard decisions.
Technical Takeaways
- —Apply a single, consistent LOPA methodology across accumulated HAZOP recommendations rather than allowing case-by-case safeguard specification
- —Periodically consolidate and review HAZOP recommendation backlogs as a program-level exercise, not only as individual action items
- —Explicitly review common cause failure dependencies across safety instrumented functions from different process campaigns sharing infrastructure
- —Issue a consolidated Safety Requirements Specification covering related safety instrumented functions to ensure basis consistency
